🇺🇦 Hacken was born in Ukraine, and we stand with all Ukrainians in our fight for freedom!

🇺🇦 Hacken stands with Ukraine!

Learn more
bg

Coinmetro Crypto Exchange: Deep Security Approach

Coinmetro Crypto Exchange: Deep Security Approach
  • Case Studies
  • bug bounty
  • crypto exchange
  • Penetration testing

16 Feb 2023

Coinmetro is Hacken’s long-time client, and we want to highlight the exchange’s unquestionable approach to security.

Coinmetro exchange brief review

Coinmetro is a centralized cryptocurrency exchange founded in 2018. The Estonia-based exchange is among the largest European custodians, with an average daily trade volume of around $1 million.

Deep security approach

Security has been the top priority for the exchange from day 1, and Hacken can attest to it. Their team incorporated a comprehensive approach to keep user deposits safe, including encryption of sensitive data, secure server infrastructure, input validation, 2FA, cold asset storage, regular audits, penetration testing, risk management, and regular library updates.

Every exchange on the crypto market is operating under a threat of cyber attacks. Ongoing threat monitoring, alert mechanisms, and swift response are crucial in mitigating a security breach. Dozens of crypto projects might fail in similar circumstances, but not Coinmetro. Ongoing threat monitoring, alert mechanisms, and swift response were crucial in mitigating a security breach. Dozens of crypto projects fail in similar circumstances, but not this one.

A security-first mindset has been a point of difference. While incidents plagued other crypto projects, Coinmetro’s reputation as an exchange improved. It remains this way.

Importance of external review 

2022 brought many alarming signals. There were times when crypto exchanges unilaterally suspended withdrawals. Most importantly, FTX’s collapse put the crypto market ablaze. Web3 projects struggled for mainstream credibility.

Concerned for the community, Coinmetro decided to integrate external review into existing security controls. Driven by the internal will to improve and make the service more secure, the team wanted to have external eyes on security solutions.

How did they choose Hacken?

After scanning the Web3 security market and gathering references, Coinmetro decided Hacken is the most trustworthy and reliable option. The team approached us because, among the well-known auditors, Hacken demonstrated excellent results – 0 hacks in 2022. Zero incidents for Hacken audited clients is strong evidence of the high quality of Hacken security standards.

Penetration testing and bug bounties

Coinmetro requested grey box penetration testing for Web / mobile apps and API. There’s also an active public bug bounty program at HackenProof.

Hacken scope of services provided has expanded over the past two years. The team remarked highly certified Hacken experts who provide tested, stable and secure environments.

Bug bounty at HackenProof

Bug bounty is an ongoing crowdsourced protection measure where external security researchers find bugs in the system for rewards. As a crowdsourced measure, a bug bounty galvanizes the most active and security-savvy part of the crypto community. Something that has always been important to Coinmetro.

The client requested a bug bounty at HackenProof for the web application and API. Researchers who find and report in-scope vulnerabilities can receive prizes of up to $3,000. The program has recently attracted 112 white-hat hackers who have submitted 59 valid reports.

Triage Service 

HackenProof Triage team validated every bug report to ensure they are in-scope and match the claimed severity level. As a result, Coinmetro is only getting relevant and verified vulnerabilities.

On top of that, HackenProof handles all the payments. The triage service has already saved countless client hours and makes crowdsourced defense as effective as possible.

Crowdsourced security for Coinmetro

The bug bounty program not only increases safety but also engages the community. The most active members can contribute to a more secure product. The ongoing program is open to the public, and anyone interested in finding bugs for rewards can join it.

Safe libraries

One way Hacken has been helpful relates to scanning and fixing libraries. Coinmetro uses stable libraries, but the extra layer of assurance won’t hurt. Among many other things, Hacken conducted frequent library scans. Proactive scanning is an instrumental step toward fixing potentially vulnerable dependencies.

Library version control is vital for secure software development, but it takes away precious engineering resources. Hacken takes care of proactive scanning and fixing libraries, freeing up developer resources for more creative tasks.

The crypto market values secure brands

Transparency and trust is the only winning approach for Web3 projects aimed at long-term success. After FTX’s incident, people started to value and notice highly secure, trustworthy, and transparent brands like Coinmetro.

From Day 1, the team focused on building a reliable exchange where hackers cannot steal users’ funds. Kevin Murcko, the CEO, gives frequent AMAs where he answers and explains everything related to strategy, innovation, safety, and compliance.

Coinmetro continues to prioritize user safety and reliability. Over the years, Hacken external review has enhanced the client’s proactive defense. Together, we continue making Web3 a safer place.

Want to improve your security?

share via social

Subscribe to our research

Enter your email address to subscribe to Hacken Reseach and receive notifications of new posts by email

[contact-form-7 id="8165" title="Subscribe"]

Interested in getting to know whether your systems are vulnerable to cyberattacks?

Reach our team

Tell us about your project

  • This field is required
  • This field is required
    • telegram icon Telegram
    • whatsapp icon WhatsApp
    • wechat icon WeChat
    • signal icon Signal
  • This field is required
  • This field is required
This field is required
departure icon

Thank you for your request

Get security score on

  • certified logo
  • coingeco logo
  • coin market cap logo

1,200+ Audited Projects

companies logos

Apply for partnership

  • This field is required
  • This field is required
  • This field is required
  • This field is required
    • Foundation
    • VC
    • Angel investments
    • IDO or IEO platform
    • Protocol
    • Blockchain
    • Legal
    • Insurance
    • Development
    • Marketing
    • Influencer
    • Other
This field is required
This field is required
departure icon

Thank you for your request

Get security score on

  • certified logo
  • coingeco logo
  • coin market cap logo

1,200+ Audited Projects

companies logos

Get in touch

  • This field is required
  • This field is required
  • This field is required
  • This field is required
This field is required
By submitting this form you agree to the Privacy Policy and information beeing used to contact you
departure icon

Thank you for your request

Get security score on

  • certified logo
  • coingeco logo
  • coin market cap logo